Any logged in user could edit any other logged in user.
High severity
GitHub Reviewed
Published
Apr 16, 2021
in
curveball/a12n-server
•
Updated Jan 27, 2023
Description
Published by the National Vulnerability Database
Apr 16, 2021
Reviewed
Apr 16, 2021
Published to the GitHub Advisory Database
Apr 19, 2021
Last updated
Jan 27, 2023
Impact
Everyone who is running a12n-server.
A new HAL-Form was added to allow editing users. This feature should only have been accessible to admins. Unfortunately, privileges were incorrectly checked allowing any logged in user to make this change.
Patches
Patched in v0.18.2
References